Professional Documents
Culture Documents
Router(config-isakmp)#authentication pre-share
Router(config-isakmp)#group 2
site B)
Bc3: Quy nh lifetime
Router(config)#crypto ipsec security-association lifetime seconds 86400
Bc7: Gn vo interface
Router(config)#interface dialer 0
Router(config-if)#crypto map MAP-VPN
SITE A ASA 5510:
Bc 1: to Connection Profiles:
Login vo ASDM v chn Menu Startup Wizards ri sau chn IPsec VPN
Wizard
Ti bc 1 chn:
+ Tick vo Site-to-Site
+ VPN Tunnel Interface chn interface: outside (WAN IP)
+ V tick chn Enable. v bm Next
- bc 2:
+ Peer IP Address in IP WAN ca router 2811 (Site A).
+ Pre-shared key: g Cisco123 (ging nh Pre-shared key router cisco 2811 site A) v
nhn Next.
Bc 2: To Access List:
Sau khi to Connection Profile xong ta tin hnh set access-list nonat cho kt ni VPN.
Lu mc nh nonat s disable, bn cn phi enable n ln trc sau mi c th
tin hnh to access-list cho nonat.
+ X du cng ti Certificate to Connection Profile v chn ACL Manager. ti
nonat click chut phi chn Add ACE
Permit cho
class mng 192.168.0.0/24 v 16.3.0/24 .